Product
Solutions
Compare
Resources
Get early access Talk to us
Backups

How to make a WordPress backup the right way

A WordPress backup is a copy of your site's files and its database, kept away from your server, so you can restore the site if it breaks, gets hacked or is deleted. Back up weekly, or daily for busy sites, and before every update. If you look after several sites, WordPress backups with verified restore can do it for all of them.

Diagram of what a complete WordPress backup contains: files (uploads, themes, plugins, wp-config.php, .htaccess and WordPress core) and the database (posts and pages, comments, users, settings, plugin data and store data), with the 3-2-1 backup rule of three copies on two types of storage with one off-site
A complete WordPress backup covers the files and the database, stored by the 3-2-1 rule.

The short answer

A complete WordPress backup has two parts: the files (themes, plugins, uploads, wp-config.php and .htaccess) and the database (posts, pages, users, settings and orders). You need both to restore a site. There are four ways to make one:

  1. A backup plugin such as UpdraftPlus, set to run on a schedule and send copies to cloud storage.
  2. Your host's backups, usually daily and kept for 14 to 30 days.
  3. A manual backup: export the database and download the files over SFTP.
  4. A management platform that backs up every site you run automatically.

Back up weekly for a small site, daily for a busy one, and always before updates. Keep three copies with one off-site, and test a restore every month.

What does a WordPress backup include?

WordPress keeps your site in two places, and a full WordPress backup copies both. As WordPress's own documentation puts it, you need both to fully restore a typical site.

  • The files. Everything in the WordPress folder: your themes, plugins and uploaded media in wp-content, the wp-config.php file with your database details and security keys, and the .htaccess file with redirects and rules. WordPress core files can be downloaded again, but backing them up does no harm.
  • The database. Usually MySQL or MariaDB, stored separately from the files. It holds posts, pages, revisions, comments, users and roles, settings, menus and widgets, data from plugins such as forms and SEO, and on WooCommerce, orders, customers and products.

Copying the files alone does not capture the database, and a database without its uploads restores a site full of broken images. One more trap: Tools > Export is not a backup. It creates an XML file of posts, pages, comments and users, but leaves out settings, themes, plugins and the media files themselves.

How often should you back up WordPress?

WordPress's documentation suggests weekly backups for smaller sites with few posts, daily backups for busy sites, and a backup before every upgrade or move. The right interval is really a question of how much work you could afford to lose:

  • Brochure site that rarely changes: weekly, plus before every update.
  • Blog or business site updated often: daily.
  • Site taking enquiries or bookings all day: daily at least, more often if each enquiry matters.
  • WooCommerce store: several times a day or in real time, because a restore loses every order placed since the last backup.

Whatever the schedule, take a fresh backup right before updates. A nightly backup can be almost a day old by the time an update breaks something. If WordPress updates itself, our guide to WordPress automatic updates explains when that happens.

Where to store WordPress backups: the 3-2-1 rule

A backup stored on the same server as the site is lost along with the server, and it is the first thing an attacker or a failed disk takes with it. The 3-2-1 rule, from US-CERT's "Data Backup Options" paper, is the standard answer:

  • 3 copies of your data: the live site and two backups.
  • 2 different types of storage, so one failure cannot take both.
  • 1 copy off-site, away from your server and your office.

WordPress's documentation says much the same: keep at least three to five recent backups, in different places. Its hardening guide adds two good habits: encrypt backups, because they contain your users' data, and keep a record of which backups you have tested.

Way 1: Back up WordPress with a plugin

For most single sites, a backup plugin is the best balance of effort and safety. Install it once, choose a schedule and a remote destination, and it runs on its own.

WordPress backup plugins compared
PluginActive installsFree versionPaid version
UpdraftPlus3 million+Scheduled backups to Dropbox, Google Drive, Amazon S3, FTP, email and more; restore by componentIncremental backups, automatic backups before updates, more destinations, migration. From $70 a year for 2 sites.
Jetpack VaultPress Backup20,000+ (standalone plugin)None: needs a paid Jetpack planReal-time cloud backups for core and WooCommerce tables, one-click restore, 10GB storage. $4.95 a month for the first year, then $9.95.
Duplicator1 million+Manual backups stored locally or in Duplicator Cloud; built for moving sitesScheduled backups, cloud storage, recovery points, multisite. From $79 for 2 sites (introductory price).
BackWPup400,000+Scheduled backups of files, database or both to Dropbox, FTP, S3 and moreMore destinations, restore from the cloud, encryption
BlogVault80,000+Free trial onlyIncremental backups stored off-site on BlogVault's servers, 30-day retention, one-click restore. From $49.50 per site a year.

Install counts from WordPress.org and prices from each vendor's site, checked 10 October 2026. Prices change and introductory discounts are common, so check before you buy.

To set one up:

  1. Install the plugin from Plugins > Add New and activate it.
  2. Choose separate schedules for files and the database. The database changes more often, so it can run more often.
  3. Connect remote storage such as Google Drive, Dropbox or an S3 bucket. Do not leave backups only on the server.
  4. Set how many backups to keep. Keep enough to go back further than the slowest problem you might miss, such as a hacked site found weeks later.
  5. Run a first backup by hand and check that both parts arrived at the destination.

One limit to know: a plugin runs inside the site it protects. If the site is down, hacked or out of disk space, the backup can fail with it, and many plugins only report failures inside wp-admin.

Way 2: Use your host's WordPress backups

Most managed WordPress hosts back up every site daily at no extra cost, and many let you restore with one click.

WordPress backups at managed hosts
HostAutomatic backupsKept for
KinstaDaily, plus up to 5 manual backups14 to 30 days depending on plan; 6-hourly and hourly backups are paid add-ons
WP EngineDaily, plus manual backup points30 days
SiteGroundDaily, plus manual copies on higher plansUp to 30 daily copies on shared hosting, up to 7 on cloud hosting

From each host's own documentation, checked 10 October 2026.

Host backups are a useful safety net, but not a complete plan. They live with the same company that runs your server, retention is fixed by your plan, restores are often whole-site only, and they go away if you change host. Download a copy now and then, and keep at least one independent backup.

Way 3: Back up WordPress manually

A manual backup takes about ten minutes and needs no plugin. It is a good habit before a big change, and a way to back up WordPress without a plugin at all. Back up the database first, then the files.

  1. Export the database. In phpMyAdmin, select the WordPress database, click Export, choose SQL format and include DROP TABLE statements. Or run wp db export from the site folder.
  2. Download the files. Connect over SFTP and download the whole WordPress folder, including wp-content, wp-config.php and .htaccess.
  3. Put copies in two more places. Keep one copy in cloud storage and one on a different device, never only on the web server.
  4. Label and test. Name the backup with the site and date, and restore it to a test location to prove it works.

If you have SSH access, WP-CLI makes it faster:

# Database: writes a .sql file named after the database and today's date
wp db export

# Files: one archive of the whole WordPress folder
tar -czf site-files-2026-10-10.tar.gz /path/to/wordpress

To restore, put the files back first, then import the database with wp db import or phpMyAdmin. Our guide on how to restore a WordPress backup covers the order and the checks in detail. Manual backups are reliable, but only when someone remembers to do them, which is why they work best as an extra, not as the plan.

Way 4: Automatic WordPress backups for every site you manage

A plugin per site works until you have several sites. Then you have several plugins to update, several storage accounts to watch and several places a backup can fail without anyone noticing. A WordPress management platform backs up every connected site from outside, on infrastructure separate from the sites themselves.

WPCentrify is built that way. (Disclosure: WPCentrify is our product.) Its WordPress backups with verified restore are part of a WordPress website management platform that also handles updates, uptime, security and client reports:

  • Incremental, encrypted and off-site. After the first full copy only changes are sent, so large sites back up quickly without timing out. Backups are encrypted with AES-256 at rest and TLS 1.3 in transit, and stored in the United States on OVHcloud servers, never on the server they protect.
  • A restore point before every change. Every update or bulk action takes a fresh snapshot first, so rolling back a safe update never depends on last night's backup.
  • Real-time backups for WooCommerce stores, so a restore does not lose the orders placed since the last scheduled run.
  • A way back after a hack. If a site is hacked, Sentinel security monitoring points you to the last backup taken before the first sign of the hack.
  • Restore testing on a schedule. WPCentrify restores a backup in an isolated sandbox, boots WordPress, checks the database and confirms the home page and admin respond, then records a dated pass or fail.
  • Restore only what you need: the whole site, files only, the database only, a single table or a single file.
  • Retention from 7 days to 12 months, set per site or per care plan tier, and any backup can be downloaded with no export fee.
  • Email alerts when a backup fails, gets older than its window or fails a restore test, and backup evidence in monthly client reports.

Backups are included on every plan, and keeping backups in your own S3-compatible storage is on the roadmap. If you run more than a few sites, it is the same work as setting up one plugin, done once for all of them.

Which WordPress backup method should you use?

Most people combine two: their host's daily backups as a safety net, plus one method they control that keeps a copy off-site.

Ways to back up WordPress compared
WayEffortOff-site copyBest for
Backup pluginLow after setupYes, if you add cloud storageMost single sites
Host backupsNoneUsually same providerA safety net on top of your own backups
Manual backupHigh, every timeOnly if you move itA one-off copy before a big change
Management platformNone per siteYes, on separate infrastructureSeveral or many sites

Our summary of the four ways described above.

Test your WordPress backups by restoring them

A backup is only proven when it has been restored. The common failures are quiet: the plugin timed out partway through a large database, the storage filled up, a password expired and the schedule stopped, or the archive was never complete. None of these show up until the day you need the backup.

WordPress's own guidance recommends checking now and then that your automated backups actually work. Once a month, restore a recent backup to a test location, open the site, log in and check a few pages and recent content. Write down how long it took: that is your real recovery time, and the number a client will ask for after an incident.

WordPress backup checklist

  • Files and database are both backed up
  • Backups run on a schedule that matches how often the site changes
  • A fresh backup is taken right before every update
  • At least one copy is stored off the server, ideally encrypted
  • Enough history is kept to go back weeks, not just days
  • Someone is emailed when a backup fails
  • A restore is tested at least once a month
  • You know how long a full restore takes

Sources

All sources checked on 10 October 2026.

Answers

Questions about WordPress backups

Back up both the files and the database. The easiest way is a backup plugin that runs on a schedule and sends copies to cloud storage. You can also use your host's backups, or do it by hand by exporting the database with phpMyAdmin or WP-CLI and downloading the files over SFTP.

Free versions of UpdraftPlus and BackWPup run scheduled backups and can send them to cloud storage such as Dropbox, Google Drive or Amazon S3. You can also export the database and download the files yourself at no cost. Many hosts include daily backups in their plans.

WordPress's own documentation suggests weekly backups for small sites with few posts and daily backups for busy sites, plus a backup before every update or move. Online stores and sites that take bookings or enquiries all day need backups several times a day or in real time.

No. Self-hosted WordPress has no full backup tool. Tools, then Export creates an XML file of your posts, pages, comments and users, but it leaves out settings, themes, plugins and the media files themselves, so it cannot restore a whole site.

Somewhere other than the server the site runs on. Follow the 3-2-1 rule: three copies, on two different types of storage, with one copy off-site. A backup kept only on the same server is lost along with the server.

They are a good start. Most managed WordPress hosts back up daily and keep copies for 14 to 30 days. But they sit with the same company that runs the server, retention is fixed, and restores are often all or nothing, so keep at least one independent copy.

It depends on the site. UpdraftPlus is the most widely used and has a capable free version. Jetpack VaultPress Backup offers real-time backups for stores. BlogVault stores incremental backups off-site on its own servers. For many sites, a management platform avoids configuring a plugin on each one.

Back up more often than a brochure site, ideally in real time or every few hours, because a restore loses every order placed since the last backup. Take a fresh backup right before every update, and check how many orders a restore would lose before you run one.

Export the database with phpMyAdmin (choose SQL format) or with the WP-CLI command wp db export, then download every file in the WordPress folder, including wp-config.php and .htaccess, over SFTP. Store both copies away from the server.

Use a management platform rather than a plugin on each site. WPCentrify backs up every connected site incrementally to encrypted off-site storage, takes a restore point before every update and tests restores on a schedule, with backup health for every site on one screen.

Early access

Back up every WordPress site, and prove it restores

Incremental encrypted backups stored off-site, a restore point before every update and scheduled restore tests for every site you manage.

Free during early access. No credit card required.